目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2026-11811— zephyrproject zephyr 资源管理错误漏洞

一分钟漏洞结论

影响对象
zephyrproject zephyr
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

zephyrproject zephyr是zephyrproject组织开源的一个面向物联网设备的实时操作系统。 zephyrproject zephyr 2.0.0版本至4.4.2之前版本存在资源管理错误漏洞,该漏洞源于subsys/mgmt/updatehub/updatehub.c文件中的start_coap_client()函数在连接建立失败路径上泄漏CoAP/DTLS套接字描述符,由于错误处理中ret标志设置不当导致清理函数未被调用,攻击者可通过网络干扰连接触发,造成套接字/net_contex

CVSS 3.7 · Low EPSS 0.40% · P32

可能的 ATT&CK 技术 1 AI

T1499 · Endpoint Denial of Service

影响版本矩阵 1

厂商产品 版本范围状态
zephyrproject zephyr 2.0.0< 4.4.2 affected
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2026-11811 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
Socket file-descriptor leak in UpdateHub OTA client start_coap_client() leading to resource-exhaustion DoS
来源: CVE Program / CVE List V5
Vulnerability Description
The UpdateHub over-the-air update client's start_coap_client() in subsys/mgmt/updatehub/updatehub.c leaks the CoAP/DTLS socket descriptor on its connection-setup failure paths. The shared error: cleanup gated socket closing on a ret > 0 flag, but ret was set to -1 immediately after the socket was created, so when zsock_setsockopt() (DTLS) or zsock_connect() subsequently failed the gate was false and cleanup_connection() was never called. The open descriptor in the global ctx.sock was then overwritten by the next attempt, permanently leaking it from the socket / net_context pool until reboot. The failing setup path is reached every time the OTA client tries to contact the UpdateHub server and the connection cannot be established — driven automatically by the periodic autohandler() poll (and on demand via the updatehub_probe()/updatehub_update() API or the updatehub run shell command). The DTLS handshake/connect outcome is influenceable by a network or on-path attacker who drops, resets, or otherwise disrupts traffic to the server, and also fails naturally whenever the server is unreachable. Each failed attempt permanently leaks one descriptor; once the shared socket pool is exhausted, networking degrades device-wide until the device is rebooted, a denial-of-service condition. Severity is low because the leak rate is bounded by the configured OTA poll interval (default once per 24 hours), the effect is gradual and recovered by reboot, and only builds with the UpdateHub client enabled are affected. There is no memory-corruption, information-disclosure, or authentication impact.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
来源: CVE Program / CVE List V5
Vulnerability Type
对已超过有效生命周期的资源丧失索引
来源: CVE Program / CVE List V5
Vulnerability Title
zephyrproject zephyr 资源管理错误漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
zephyrproject zephyr是zephyrproject组织开源的一个面向物联网设备的实时操作系统。 zephyrproject zephyr 2.0.0版本至4.4.2之前版本存在资源管理错误漏洞,该漏洞源于subsys/mgmt/updatehub/updatehub.c文件中的start_coap_client()函数在连接建立失败路径上泄漏CoAP/DTLS套接字描述符,由于错误处理中ret标志设置不当导致清理函数未被调用,攻击者可通过网络干扰连接触发,造成套接字/net_contex
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商 产品 影响版本 CPE 订阅
zephyrproject zephyr 2.0.0 ~ 4.4.2 -

二、漏洞 CVE-2026-11811 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-11811 的情报信息

请登录查看更多情报信息。

CVE-2026-11811 补丁与修复 (1)

CVE-2026-11811 厂商安全公告 (1)

同批安全公告 · zephyrproject · 2026-08-10 · 共 5 条

CVE-2026-8718 8.4 HIGH zephyrproject zephyr 缓冲区错误漏洞
CVE-2026-11810 7.5 HIGH zephyrproject zephyr 异常处理不当漏洞
CVE-2026-11809 3.7 LOW zephyrproject zephyr 缓冲区错误漏洞
CVE-2026-11812 2.5 LOW zephyrproject zephyr 竞争条件问题漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2026-11811

暂无评论


发表评论